CVE-2026-75600
Last modified
CVE-2026-75600 is a high-severity vulnerability rated 8.6/10 on the CVSS scale. FreePBX is an open source IP PBX. Prior to version 17.0.9, authenticated users who are authorized to access the GraphQL api module interface of FreePBX are able to execute arbitrary shell commands.
Description
FreePBX is an open source IP PBX. Prior to version 17.0.9, authenticated users who are authorized to access the GraphQL api module interface of FreePBX are able to execute arbitrary shell commands. Authenticated access to the api module is required. The PBX API module's documentation generator accepts an authenticated host parameter and uses it to build a shell command. The code path validates the generated OAuth access token before execution, but it does not validate or escape host. Compromise results in authenticated arbitrary shell command execution as the FreePBX web/PBX service user (typically asterisk.). This issue has been patched in version 17.0.9.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| FreePBX | security-reporting | < 17.0.9 |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-75600?
How severe is CVE-2026-75600?
How do I fix CVE-2026-75600?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7559The Affilia – Affiliate Program & Referral Tracking for Word…4.3
- CVE-2026-75592Kirby is an open-source content management system. Prior to …6.9
- CVE-2026-75593BuildKit is a toolkit for converting source code to build ar…7.2
- CVE-2026-75594Kirby is an open-source content management system. Prior to …8.2
- CVE-2026-75595Netty is an asynchronous, event-driven network application f…9.1
- CVE-2026-75596Netty is an asynchronous, event-driven network application f…7.5
- CVE-2026-75601Static Web Server (SWS) is a production-ready web server sui…4.3
- CVE-2026-75602OpenList a file list program that supports multiple storage.…6.5
- CVE-2026-75604Next.js is a React framework for building full-stack web app…9
- CVE-2026-75607Frigate is an open source network video recorder. Prior to 0…8.1
- CVE-2026-75608Frigate is an open source network video recorder. Prior to 0…7.7
- CVE-2026-7561The Tm – WordPress Redirection plugin for WordPress is vulne…6.1
Are you affected by CVE-2026-75600?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
